The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.
CVE ID: CVE-2024-8700
Vendor: Unknown
Product: Event Calendar
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 13.04% (scored less or equal to compared to others)
EPSS Date: 2025-06-04 (when was this score calculated)